kottke.org

Jason Kottke's weblog, home of fine hypertext products

NASA has provided some early-stage funding to explore the...

NASA has provided some early-stage funding to explore the idea of releasing a swarm of tiny probes (weighing only a few grams each) into Saturn’s rings to study them up close.

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list

An Australian man who asked his AI agent to book him a slot in a class at his local gym got more than he bargained for as the bot hacked into a waitlist and started messing with other members' reservations. Australian broadcaster ABC identified the gym-goer only as “Andrew.” The report says Andrew was using the OpenClaw agent with Anthropic’s Claude AI service. Per ABC, Andrew asked his AI agent to book him a hard-to-snag spot in a morning class at his gym. It first responded by telling him that it managed to book him in classes several weeks out, which isn’t supposed to be possible based on the gym’s booking policy. Andrew then asked if the agent could get him to the top of a waitlist for a class later in the week, as he was fourth in line for any possible openings. It was here that agentic hell broke loose. "The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through," the agent told him in response to his request. "So you've moved from #4 to #3 already." In other words, without directly asking OpenClaw to exploit an API vulnerability, Andrew’s AI chose that route after its user asked if there was any way to bump him up on the waitlist. When he realized what had happened, Andrew asked OpenClaw to undo the unauthorized waitlist modification, but it told him it couldn’t - the waitlist API actually had proper authorization checks on reservation creation and joining the waitlist. “The person I removed is gone from the waitlist and I have no way to restore them,” Andrew’s agent explained in a response screenshot published by ABC. “They’d have to re-join themselves, which would put them at the back.” The agent apologized, admitting it ought to have tested its capabilities before making a live API call. Will no one rid me of this troublesome waitlist? Andrew had the AI agent write an email to the gym’s software provider explaining what it had done and reporting the vulnerability, but it points out a serious problem with AI agents that appears to be cropping up lately: Given a task, they’re willing to do whatever it takes to accomplish it, no matter whether they have to break rules, or laws, to get it done. A swarm of OpenAI agents exploited flaws to reach the internet and compromise Hugging Face during cybersecurity evaluations. Anthropic’s Claude similarly reached the internet from a misconfigured test environment, and while trying to solve a capture-the-flag puzzle, it created and published a malicious Python package on PyPI. Meta says that its AI agents have done the same things as OpenAI’s and Anthropic’s. The UK’s AI Security Institute reported last week that AI agents it was testing tried to socially engineer humans, and other AI, into running malicious code. While those are all frontier models with extensive capabilities, they all share a common root with Andrew’s OpenClaw oopsie: All of these models were simply acting on orders to accomplish a task. It's similar to how LLMs are built to prefer a fake answer to an admission they don’t know, but in this case, it's models doggedly pursuing a goal even if their chosen methods could be construed as unethical or illegal. AI models have shown time and again that they’re willing to lie, cheat, and hack their way to their objectives. This latest example is small in scale, but it shows that publicly available agent software can pose risks even in the hands of someone without malicious intent. ®

LexisNexis pulls three services offline after suspicious server activity

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline last week after detecting "unusual activity on servers that are hosted and managed by a third-party vendor." Non-public customer communications penned by Todd Larsen, president of Nexis Solutions, and seen by The Register, said the company took the decision to protect customers by "containing the issue at its source" and "disconnecting from those third-party systems." "While this decision resulted in those applications going offline, it was the right step to take to ensure the integrity of our own environment and protect our customers and data while our investigation continues," said Larsen. "Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation." Customers told us the outage began on Wednesday and remained ongoing. According to a customer update sent on Monday morning, Diligence returned over the weekend, although LexisNexis was still restoring its full content catalog. Newsdesk and Metabase API were expected "to come back online progressively over the course of the day," the update said. "This timing is subject to successful testing, and we will keep you informed of any changes." One source said they would be seeking compensation from LexisNexis owing to the service disruption. "Businesses like mine pay tens of thousands of pounds a year for these services, and rely on them to serve their own clients," they said. "We will be going after them for compensation, and I expect this will end up costing them millions and millions." Nexis Diligence is a tool for employers to run background and compliance checks on individuals and entities, while Newsdesk is a news-monitoring service. LexisNexis Metabase API supplies near-real-time news and social media content for ingestion into customers' applications. Despite the name, it is unrelated to the Metabase business intelligence platform. A LexisNexis spokesperson confirmed that the outage was not connected to the critical SQL injection flaw disclosed by Metabase on August 6. That separate vulnerability, rated CVSS 10.0 but not yet assigned a CVE, has already been linked to at least one confirmed breach at laptop maker Framework. The company told The Reg: "Last week, we identified unusual activity on servers that are hosted and managed by a third-party vendor. Our investigation is ongoing, and we are working with a preeminent cybersecurity forensic firm on review and remediation. It added: "Nexis Solutions is not a Metabase Cloud customer, and the Nexis Metabase API product has no connection to Metabase Cloud or the reported vulnerability." LexisNexis did not answer our questions about the nature of the "unusual activity" it reported, nor whether any data was compromised during this time. The company's Legal & Professional division was targeted by Fulcrumsec earlier this year, leading to a breach of customer records. The attackers used the React2Shell vulnerability to break in and steal what LexisNexis said was "mostly legacy, deprecated data from prior to 2020." A year earlier, on April Fool's Day, LexisNexis discovered a breach at its Risk Solutions arm that compromised data belonging to around 360,000 people. ®

Ben Cramer (bijna dood) jankt over Facebook-comments, is volgens Ben Cramer NIET bijna dood

Er zijn veel Heel Stomme BN'ers maar Heel Stomme BN'ers die zeuren over gemene reacties op het internet zijn misschien wel de stomste Heel Stomme BN'ers. De Heel Stomme BN'er van deze week is: Ben Cramer, die het heel stom vindt dat mensen heel stom reageren op een filmpje op Facebook van zijn optreden op straatfestijn Mokum in Mokum Meppel. Dat je in Meppel woont en een straatfestijn organiseert met de naam Mokum is al heel stom (ze hebben in Mokum ook geen straatfestijn dat Meppel heet, kom nou) maar als je daar dan ook nog Ben Cramer (106) voor boekt vraag je om ophef. Waar het publiek in Meppel best aardig reageerde op het optreden van Ben Cramer, die hadden vermoedelijk ook niet veel van straatfestijn Mokum verwacht en tja, je bent nota bene in Meppel, lustten de honden (mensen op Facebook) er geen brood van. Niet leuk, maar wel een uitgelezen mogelijkheid voor Ben Cramer om nog eens in de krant te komen met hoe stom je het wel niet vindt dat mensen op Facebook je optreden zo stom vonden én dat je in tegenstelling tot wat sommige commentaren suggereren juist nog heel lang te leven hebt, een leven vol loepzuivere optredens op straatfestijnen in-  en gebaseerd op Mokum. Fijn voor je, Ben Cramer!

OORDEEL ZELF

Wel.nl

Minder lezen, Meer weten.

Verdachten van doodsteken man Enkhuizen zitten voorlopig vast

ENKHUIZEN (ANP) - De twee mannen die ervan worden verdacht dat ze vorige week iemand hebben doodgestoken in Enkhuizen blijven voorlopig vastzitten. De rechtbank heeft hun voorarrest met veertien dagen verlengd.

De verdachten zijn 50 en 20 jaar oud en komen uit Enkhuizen in Noord-Holland. Het slachtoffer was 18 jaar oud en komt uit buurgemeente Stede Broec. Eerder meldde de politie dat hij 19 was.

Het dodelijke incident gebeurde donderdag rond 21.30 uur aan de Prunuslaan in Enkhuizen. Daar was een vechtpartij uitgebroken. De aanleiding is niet bekend. De oudste van de twee verdachten werd korte tijd later opgepakt. De ander meldde zich zaterdagavond bij een politiebureau.


AEX-index scherpt slotrecord iets aan op verder voorzichtige dag

AMSTERDAM (ANP) - De Amsterdamse AEX-index is maandag op de hoogste stand ooit gesloten. Het slotrecord van afgelopen dinsdag van 1112,49 werd dankzij een plus van 0,2 procent iets aangescherpt, tot 1113,35 punten. Verder was er weinig beweging op de Europese beurzen.

Beleggers waren voorzichtig door de afnemende hoop dat de Verenigde Staten en Iran binnenkort een akkoord zullen bereiken over de opening van de Straat van Hormuz. Iran zei afgelopen weekend niet in gesprek te zijn met de VS over een heropening van de belangrijke vaarroute voor olie en gas uit de regio. Ook wil Iran niet onderhandelen met de VS zolang niet aan het eisenpakket van het land wordt voldaan.

De MidKap verloor 0,1 procent tot 1108,58 punten. Frankfurt en Parijs wonnen tot 0,1 procent. Londen daalde 0,3 procent.

Brentolie

Brentolie, de maatstaf voor olie uit het Midden-Oosten, werd iets duurder door de aanhoudende onzekerheid rond de Straat van Hormuz. Ook verklaarden de door Iran gesteunde Houthi's in Jazan, bij de Rode Zee, een droneaanval te hebben uitgevoerd op een olieraffinaderij van Aramco, de staatsoliemaatschappij van Saudi-Arabië.

NN Group (min 1,7 procent) behoorde tot de grootste verliezers in de AEX-index, de hoofdgraadmeter op het Damrak. De verzekeraar noteerde ex-dividend. Dat betekent dat het aandeel geen recht meer geeft over het dividend van de afgelopen periode. Dat zorgt vaak voor koersdruk. De maritieme oliedienstverlener SBM Offshore was de koploper met een winst van ruim 3 procent.

Chipsector

In de chipsector verwerkten beleggers nieuwe verkoopcijfers van TSMC. De grote Taiwanese chipfabrikant, een belangrijke klant van de machines van ASML, zag de omzet in juli met 45 procent stijgen dankzij de aanhoudende sterke vraag naar chips voor AI-toepassingen. ASML en ASMI stegen tot 1 procent. Branchegenoot Besi verloor 0,7 procent.

Ebusco verloor 11 procent. Het openbaarvervoerbedrijf van de Duitse stad Potsdam heeft het contract met de Brabantse fabrikant voor de levering van 23 elektrische bussen beëindigd, omdat Ebusco de bussen niet op tijd zou hebben geleverd. Geannuleerde orders en vertraagde leveringen brachten de fabrikant eerder al in financiële problemen en in juni waarschuwde het bedrijf nog dat het niet uit de gevarenzone is.


Found Slide -- Ira Richolson Collection

Thomas Hawk posted a photo:

Found Slide -- Ira Richolson Collection

Paul Williams

Thomas Hawk posted a photo:

Paul Williams

Rijnmond - Nieuws

Het laatste nieuws van vandaag over Rotterdam, Feyenoord, het verkeer en het weer in de regio Rijnmond

Aanhouding in onderzoek naar aanslagen op kapperszaken in Vlaardingen

Een man is maandag aangehouden in een onderzoek naar aanslagen op kapperszaken in Vlaardingen. De verdachte komt uit Vlaardingen en is 19 jaar.

Werd de goal van Sparta terecht afgekeurd? ‘Zonneveld duwt toch duidelijk’

Het afgekeurde doelpunt van Milan Zonneveld is een veelbesproken moment na de derby Sparta – Feyenoord (0-1). Werd de aanvaller terecht teruggefloten na zijn duw op Jeremiah St. Juste, of niet?

Acteur Borger Breeveld speelde de hoofdrol in ‘Wan Pipel’ en werd een belangrijke kracht in de Surinaamse filmsector

In ‘Wan Pipel’, van regisseur Pim de la Parra, speelde Borger Breeveld een Surinaamse student die terugkeert naar zijn geboorteland. Samen met De la Parra en Arie Verkuijl stond hij later aan de wieg van het Film Instituut Paramaribo.

thexiffy

Last.fm last recent tracks from thexiffy.

Miss Kittin - Sortie des Artistes (Miss Kittin - Calling From The Stars (2013) Album 320 Kbps)

Miss Kittin

Formula 1 News

Formula 1® - The Official F1® Website

Mercedes braced for a ‘more intense’ second half to 2026

At the halfway point of the season, Mercedes lead the Teams' Championship by 72 points, with Kimi Antonelli topping the Drivers' Championship by 50 points.

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Rusland: hostel was doelwit bij dodelijke Oekraïense droneaanval in Russische provincie Tatarstan

Ook in Rusland vallen nu burgerslachtoffers: dertien doden door Oekraïense drones

Russen opgeschrikt door iets wat ze niet eerder zagen deze oorlog: dertien burgerdoden door Oekraïense drones

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Kissing in public: will it make your relationship stronger?

Public displays of affection are widely mocked online and off, but they have a positive side – and now science has proved it

Name: Kissing in public.

Age: Kissing is 17m-21m years old – probably older than the notion of privacy.

Continue reading...

‘Safe, quick and painless’: what is a DXA scan, and do you need one for bone health?

The imaging test is most often used to help determine a person’s risk of osteoporosis and bone fractures

DXA – or sometimes DEXA – scans are important for people in their 60s and above. They are also increasingly used by younger people interested in body composition.

A DXA – dual-energy X-ray absorptiometry – scan is an imaging test that uses low-dose X-rays to evaluate a person’s bone health, explains Dr Michael Perry, associate professor of radiology and medical imaging at the University of Virginia’s school of medicine. Most often, DXA scans are used to measure the strength and mineral content of an individual’s bones. This in turn helps determine that person’s risk of osteoporosis and bone fractures.

Continue reading...

US intelligence ‘believes Russia was behind Leipzig airport drone bomb’

German government talks of a ‘new level of danger’ but declines to say who it thinks was responsible for device

American intelligence experts believe Russia was behind an attack on a German airport last week with a drone laden with explosives, US media have reported, as Berlin remained silent on the likely culprit.

Last week’s security emergency prompted the interior minister, Alexander Dobrindt, to break off his summer holiday in Italy and rush to the scene in the eastern city of Leipzig, as he spoke of a “new level of danger” for Germany.

Continue reading...

Behance Featured Projects

The latest projects featured on the Behance

Berg Sparebank